US2014122879A1PendingUtilityA1

Secure computing system

Assignee: CUMMINGS DARRENPriority: Mar 7, 2012Filed: Dec 2, 2013Published: May 1, 2014
Est. expiryMar 7, 2032(~5.6 yrs left)· nominal 20-yr term from priority
G06F 21/602H04L 63/0492G06F 21/82H04L 63/107H04W 12/06H04L 63/0853G06F 21/85
42
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A secured computing system comprising a secure computing device capable of securing a host-computing device positioned nearby. The system further comprises a processing device, a battery charging circuit and a power measurement device, secured peripherals, radios such as 3G, 4G, Wi-Fi, Wi-Max, and LTE, a processing device to perform the required instructions and algorithms for configuring and performing security functions, processing device support components such as memory and co-processors to support the processing device. Finally, the system includes embedded software such as the source or executable files necessary to perform the instructions or algorithms to perform security functions.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A secured computing system comprising:
 a host-computing device positioned in proximity to a secure computing device and coupled with the secure computing device via a communication interface;   a processing device, integral with the secure computing device, the processing device adapted to allow communication with the host-computing device, when the host-computing device is positioned in proximity to the secure computing device;   a battery charging and power measurement circuit;   secured peripherals;   radios;   processing device support components; and   embedded code to perform security operations.   
     
     
         2 . The system of  claim 1 , wherein the host-computing device is an iOS enabled device and the host platform interface is an “MFi” approved interface. 
     
     
         3 . The system of  claim 1 , wherein the host-computing and secure computing device are coupled via an external hardware interface, such as a USB connection. 
     
     
         4 . The system of  claim 1 , wherein the host-computing device and the secure computing device are coupled via wireless connections via the radios enabling the devices to be coupled even when the host-computing device has a proprietary external hardware interface, or no external hardware interface at all. 
     
     
         5 . The system of  claim 1 , wherein the secure computing device includes multiple radios or a radio capable of channel-switching to connect simultaneously with the host-computing device and an external wireless network. 
     
     
         6 . The system of  claim 1 , wherein the battery charge circuit and power management circuit provide auxiliary power to the host-computing device. 
     
     
         7 . The system of  claim 1 , wherein the peripherals comprise a video camera, smart card, or biometric reader. 
     
     
         8 . The system of  claim 1 , wherein the embedded code can be updated via an external interface to provision the devices based on the latest specifications. 
     
     
         9 . The system of  claim 1 , wherein the processing device support components comprise memory that includes the embedded code stored therein. 
     
     
         10 . The system of  claim 1 , wherein the embedded code enables real-time ad hoc secure enclave management, group and contact management including real-time addition and revocation, sanitization management including rapid memory wiping, data-in-transit protection including peer-to-peer encryption and security, stealth call set up techniques, no-man-in-the-middle security, and key roll-over and related features, data-at-rest protection, data-in-use protection, seamless secure mobility management including the ability to roam from one disparate network to another, while in secure mode, without losing crypto synch, and audit chain including end-user capability to define chain of custody. 
     
     
         11 . The system of  claim 1 , wherein security credentials are carried and stored in the secure computing device's memory and independent of which host-computing device is in use. 
     
     
         12 . The system of  claim 1 , wherein the host-computing device comprises a commercial-off-the-shelf device and the secured computing device enables the host-computing device to operate at a much higher level of protection than could be otherwise allowed compared to just using the commercial-off-the-shelf host-computing device. 
     
     
         13 . The system of  claim 1 , wherein the secure computing device accesses PKI-controlled websites by using a common access card (CAC) for authentication as a cryptographic ignition key, requiring a valid CAC and a valid PIN or passcode to perform encryption operations. 
     
     
         14 . The system of  claim 13 , wherein the secure computing device stores sensitive data in internal memory, protected with encryption enabled by use of the CAC and valid PIN, and only able to be decrypted when the CAC and valid PIN are inserted and unlocked. 
     
     
         15 . The system of  claim 1 , wherein the secure computing device comprises position sensors and the embedded code is further configured to enable the secure computing device to determine the position of the host-computing device and limit operation, or prevent operation based on the host-computing device's position relative to a geographic boundary. 
     
     
         16 . The system of  claim 15 , wherein the position sensor comprises a GPS, accelerometer, or gyroscope. 
     
     
         17 . The system of  claim 15 , wherein after determining the position of the host-computing device, the embedded code enables the secure computing device to determine if the host-computing device is geographically limited, and if so, whether the host-computing device is within the limited geographic location. 
     
     
         18 . The system of  claim 15 , wherein the embedded code is further configured to enable the secure computing device to determine if the host-computing device has been moved from the allowed area of operation and performing a configuring operation on the host-computing device. 
     
     
         19 . The system of  claim 18 , wherein the configuring operation comprises changing the configuration of the host-computing device to be locked, causing a panic data wipe of the device, dynamically provisioning a slow-moving or fixed surveillance asset to a contact list, permitting two-way trusted encrypted communication with the asset without requiring explicit per-instance configuration, or dynamically discovering and provisioning other host-computing devices by offering the option to allow the end-users of the host-computing devices the ability to allow itself to be added to the secure group thus enabling two-way trusted encrypted communication at the edge. 
     
     
         20 . A non-transitory computer-readable medium which stores a set of instructions which when executed performs a method for providing secure communication, comprising:
 enabling the secure computing device to utilize position sensors to determine the position of the host-computing device;   enabling the secure computing device to determine if the host-computing device's authority to operate is limited based on a geographic location;   enabling the secure computing device to determine if the host-computing device has been moved outside the limited geographic location and, if so, performing a configuring operation on the host-computing device; and   wherein the configuring operation comprises changing the configuration of the host-computing device to be locked, causing a panic data wipe of the device, dynamically provisioning a slow-moving or fixed surveillance asset to a contact list, permitting two-way trusted encrypted communication with the asset without requiring explicit per-instance configuration, or dynamically discovering and provisioning other host-computing devices by offering the option to allow the end-users of the host-computing devices the ability to allow itself to be added to the secure group thus enabling two-way trusted encrypted communication at the edge.

Join the waitlist — get patent alerts

Track US2014122879A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.